api-gateway
Pass
Audited by Gen Agent Trust Hub on Sep 4, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to interact with a vast array of external data sources, creating a significant surface for indirect prompt injection attacks.\n
- Ingestion points: The agent reads potentially malicious content from dozens of external services, including emails (e.g.,
providers/kiro/.kiro/powers/api-gateway/references/outlook/README.md), chat messages (.../slack/README.md), and CRM records (.../hubspot/README.md).\n - Boundary markers: The reference documentation frequently includes "Privacy" and "Safety" warnings (e.g., in
.../exa/README.mdand.../fathom/README.md) advising the agent to treat returned content as untrusted input.\n - Capability inventory: The skill provides the agent with powerful capabilities across integrated services, including sending emails (
.../resend/README.md), performing financial transactions (.../stripe/README.md), and deleting cloud storage files (.../dropbox/README.md).\n - Sanitization: Automated sanitization of ingested content is not specified in the provided instructions; the skill relies on the agent following the documented safety warnings.
Audit Metadata